Microsoft · Agentic security

Microsoft AI Code Security

Governed intelligence profile for Microsoft AI Code Security

First observed 2026-08-27 · Last verified 2026-08-27 ·FRESH · ASI-1.0 · ASI-TAXONOMY-1.1

Lifecycle

UNKNOWN — no evidence-backed lifecycle event recorded.

Agents

UNKNOWN — no named agent is established by current evidence.

Autonomy and control

UNKNOWN — autonomy facets have not been established.

Architecture

Microsoft AI Code Security documents a multistage prepare/scan/validate/deduplicate pipeline using risk ranking, taint analysis, LSP type resolution, and multi-model debate.

AFFIRMED

The scanning stage documents more than 100 specialized AI agents targeting vulnerability classes, including injection, memory-safety, and auth-bypass auditors.

AFFIRMED

Capabilities

Remediation

The Defender CLI can generate and apply code fixes directly from agentic scan results.

AFFIRMEDCLI-invoked workflow; approval, branch, and repository permission controls are not specified.

Capability evidence

Vendor documentation
HIGH
Public demonstration
NONE_FOUND
Independent validation
NONE_FOUND
Production effectiveness
UNKNOWN

ASI-1.0: Rows represent evidence categories; assertion support confidence is intentionally not rendered beside the capability name.

Assertion support

HIGH under ASI-1.0:HIGH for quote-to-assertion support; truth not independently confirmed

Alert Triage

Agentic code-scanning findings are published to Microsoft Security Exposure Management for organization-wide triage.

AFFIRMEDRequires Microsoft Security Exposure Management.

Capability evidence

Vendor documentation
HIGH
Public demonstration
NONE_FOUND
Independent validation
NONE_FOUND
Production effectiveness
UNKNOWN

ASI-1.0: Rows represent evidence categories; assertion support confidence is intentionally not rendered beside the capability name.

Assertion support

HIGH under ASI-1.0:HIGH for quote-to-assertion support; truth not independently confirmed

Vulnerability Validation

The scanner claims broad language support with specially tuned expertise for C, C++, Java, and C#.

AFFIRMEDVendor-documented coverage; no comparative language benchmark supplied.

Capability evidence

Vendor documentation
HIGH
Public demonstration
NONE_FOUND
Independent validation
NONE_FOUND
Production effectiveness
UNKNOWN

ASI-1.0: Rows represent evidence categories; assertion support confidence is intentionally not rendered beside the capability name.

Assertion support

HIGH under ASI-1.0:HIGH for quote-to-assertion support; truth not independently confirmed

Evidence conflicts

No open conflict is recorded for this system.

Recent changes

ARCHITECTURE_CHANGE

Microsoft AI Code Security documents a multistage prepare/scan/validate/deduplicate pipeline using risk ranking, taint analysis, LSP type resolution, and multi-model debate.

ARCHITECTUREEVALUATIONRISK

AGENT_ADDITION

The scanning stage documents more than 100 specialized AI agents targeting vulnerability classes, including injection, memory-safety, and auth-bypass auditors.

ARCHITECTUREEVALUATIONRISK

CAPABILITY_ADDITION

The Defender CLI can generate and apply code fixes directly from agentic scan results.

AUTHORIZATIONOPERATIONSRISK

CAPABILITY_ADDITION

Agentic code-scanning findings are published to Microsoft Security Exposure Management for organization-wide triage.

ARCHITECTUREOPERATIONSPROCUREMENT

AVAILABILITY_LIFECYCLE_CHANGE

Microsoft AI Code Security is in preview across listed Azure commercial regions, with UAE limited to MDASH CLI scans.

DEPLOYMENTPROCUREMENTRISK

CAPABILITY_ADDITION

The scanner claims broad language support with specially tuned expertise for C, C++, Java, and C#.

EVALUATIONPROCUREMENT

Unknowns

Any evidence-panel row marked UNKNOWN is not a negative capability claim. Any NONE_FOUND row means the current governed corpus contains no qualifying evidence.

Sources

Compare claims with evidence categories